• CVE-2024-34397

发布时间: 2024年7月5日

修改时间: 2024年7月5日

概要

An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.

CVSS v3 指标

NVD openEuler
Confidentiality None
Attack Vector Local
CVSS评分 N/A 3.8
Attack Complexity Low
Privileges Required Low
Scope Changed
Integrity Low
User Interaction None
Availability None

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-3117 glib2 security update 2024年7月5日
KylinSec-SA-2024-3653 glib2 security update 2024年7月5日

影响产品

产品 状态
KY3.4-5A glib2 Fixed
KY3.5.2 glib2 Fixed
V6 glib2 Fixed